@bitbonsai/mcpvault
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @bitbonsai/mcpvaultpage 1 of 1
- CVE-2026-57441MEDIUMEG 0.0✓ Fixed in 0.11.42026-06-18
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence On case-insensitive filesystems (macOS, Windows), PathFilter compiled its deny-list patterns case-sensitively and matched the path verb…
- CVE-2026-57442MEDIUMEG 0.0✓ Fixed in 0.11.52026-06-19
MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested PathFilter's deny-list glob patterns are anchored, so `.git`, `.obsidian`, and `node_modules` were only blocked at the vault r…
Check whether @bitbonsai/mcpvault is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @bitbonsai/mcpvault CVEs against the assets you own.
Start Free Scan →